
CVE-2026-30842 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenticated user to delete avatar files uploaded by … https://www.cve.org/CVERecord?id=CVE-2026-30842
Post summary
The post announces CVE-2026-30842, noting that before version 4.6.2 an authenticated user could delete avatar files, a flaw that is fixed in the listed release.


